Bug 1149395 (CVE-2015-9382) - VUL-1: CVE-2015-9382: freetype2: buffer over-read in skip_comment in psaux/psobjs.c because ps_parser_skip_PS_token is mishandled in an FT_New_Memory_Face operation
Summary: VUL-1: CVE-2015-9382: freetype2: buffer over-read in skip_comment in psaux/ps...
Status: RESOLVED FIXED
Alias: CVE-2015-9382
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/241648/
Whiteboard: CVSSv3:SUSE:CVE-2015-9382:4.4:(AV:L/A...
Keywords:
Depends on:
Blocks:
 
Reported: 2019-09-04 13:03 UTC by Alexandros Toptsoglou
Modified: 2024-05-06 12:46 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexandros Toptsoglou 2019-09-04 13:03:27 UTC
CVE-2015-9382

FreeType before 2.6.1 has a buffer over-read in skip_comment in psaux/psobjs.c
because ps_parser_skip_PS_token is mishandled in an FT_New_Memory_Face
operation.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-9382
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-9382
https://savannah.nongnu.org/bugs/?45922
http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/src/psaux/psobjs.c?id=db5a4a9ae7b0048f033361744421da8569642f73
Comment 1 Alexandros Toptsoglou 2019-09-04 13:07:55 UTC
The fix is available at [1] (version 2.6.1). The fix seems applicable to the currently supported and older versions of freetype2. Based on this the following codestreams are tracked as affected: 

SUSE:SLE-10-SP3:Update 
SUSE:SLE-11:Update 
SUSE:SLE-12:Update 

Instructions for reproducing the issue can be found at [2]. 

My attempt to reproduce the issue in SLE11 was not successful.

[1] http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/src/psaux/psobjs.c?id=db5a4a9ae7b0048f033361744421da8569642f73

[2] https://savannah.nongnu.org/bugs/?45922
Comment 4 Thomas Leroy 2024-05-06 12:46:58 UTC
All done, closing.